CVE-2020-2242: Jenkins Database
Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.
A missing permission check in Jenkins database Plugin 1.6 and earlier allows attackers with Overall/Read access to Jenkins to connect to an attacker-specified database server using attacker-specified credentials.
Affected products
- Jenkins Database: up to and including 1.6
Published 2020-09-01. Last modified 2026-06-17.